| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9v7f-9g4p-ffgj | PyJWT: PyJWKClient follows redirects when fetching JWKS |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 29 Sep 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jpadilla
Jpadilla pyjwt |
|
| Vendors & Products |
Jpadilla
Jpadilla pyjwt |
Mon, 28 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced redirect. As a result, PyJWKClient follows the redirect and consumes the redirected response as key material. Consequently, forwarded credentials may be disclosed or verification keys may be substituted. This issue is fixed in version 2.14.0. | |
| Title | PyJWT: PyJWKClient follows redirects when fetching JWKS | |
| Weaknesses | CWE-200 CWE-345 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-01T14:56:29.970Z
Reserved: 2026-09-28T20:11:16.658Z
Link: CVE-2026-102267
Updated: 2026-10-01T14:56:26.283Z
Status : Awaiting Analysis
Published: 2026-09-28T21:17:14.430
Modified: 2026-10-01T15:17:25.350
Link: CVE-2026-102267
OpenCVE Enrichment
Updated: 2026-09-29T18:15:08Z
Github GHSA